Technically, if you wanted to insert malicious software into an update that is signed, one way do it might be to find a nonsense piece of text that - when hashed - appears to match an existing hash from other contents.
That's the reason MD5 is useless now - you can pad almost any data to make it have almost any MD5 that you like if you spend enough time.
But, I have to admit, it sounds more like corruption, junk, internal testing, a mistake, etc. than anything else. But WE cannot be sure. Only MS can provide that answer. It wouldn't be unusual for a false-Microsoft-cert to be signed by some high-up certificate authority "for testing" which leaks out and allows someone to generate a valid, signed update with whatever they wanted in it.